All trust topics

Trust Center

Responsible Disclosure

Help us investigate a potential security vulnerability safely.

Content updated: October 1, 2026

What to Include

  • The affected URL, component and time observed.
  • Reproduction steps using accounts and data you control.
  • The expected behaviour, actual result and potential impact.
  • Redacted evidence that demonstrates the issue without exposing other people's data.
  • A way to contact you and any proposed disclosure timeline.

Coordinate Active Testing

Contact us to agree the scope before active security testing. Do not access, alter, retain or publish another person's data. Stop immediately if you encounter data you do not control.

  • Do not run denial of service or disruptive scanning.
  • Do not use phishing, social engineering or unsolicited messages.
  • Do not test third party infrastructure without its owner's permission.
  • Use only the minimum evidence needed to describe the issue.

Coordinated Disclosure

Give the team an opportunity to investigate and agree a disclosure timeline. This page does not establish a paid bounty, a guaranteed response deadline or a blanket authorisation to test third party systems.